首页> 外国专利> Increased security through ephemeral keys for software virtual contactless card in a mobile phone

Increased security through ephemeral keys for software virtual contactless card in a mobile phone

机译:通过临时密钥为手机中的软件虚拟非接触式卡提高安全性

摘要

Allowing a Trusted Application (TA) on a mobile device to perform a transaction with a reader device by obtaining a transient identifier (IDn) for the mobile by combining a hardware related component, such as an unique identifier (UID) of an integrated circuit and a software related component, such as a time stamp, emitting the IDn to a provisioning server; calculating, using the master key (MK) on the server and the IDn, a transient derived key (DKn); sending the DKn from the server to the mobile, allowing the TA to securely communicate with a reader during a time interval. Also, allowing a TA to securely communicate using Near Field Communication (NFC) which are secured by symmetric cryptography, comprising: obtaining an IDn as above and transmitting it a server; calculating a DKn as above and sending it from the server to the mobile; sending the IDn to the reader device which checks the validity by reviewing the software related component; and, if valid, the DKn is calculated in the reader device using the MK and the IDn, and used to send an encrypted message to the mobile; the message is decrypted to authenticate the mobile and, if successful, allows secure reader-mobile communications.
机译:通过结合硬件相关组件(例如集成电路的唯一标识符(UID))来获取移动设备的瞬态标识符(IDn),从而允许移动设备上的可信应用程序(TA)与读取器设备执行事务处理与软件相关的组件(例如时间戳),将IDn发送给预配置服务器;使用服务器上的主密钥(MK)和IDn计算瞬态派生密钥(DKn);将DKn从服务器发送到移动设备,从而允许TA在一定时间间隔内与阅读器进行安全通信。另外,允许TA使用通过对称密码术保护的近场通信(NFC)来安全地通信,包括:如上所述获得IDn,并将其发送给服务器;以及如上所述计算DKn,并将其从服务器发送到手机;将IDn发送给阅读器设备,该阅读器设备通过检查软件相关组件来检查有效性;如果有效,则使用读取器设备中的MK和IDn计算DKn,并用于将加密消息发送给移动台;消息被解密以验证移动设备,如果成功,则允许安全的读取器-移动设备通信。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号